Security Lab.Secure by design, with the evidence regulators ask for.

We build security into delivery: threat models before code, secure review on every pull request, and dependency and secrets scanning in the pipeline. For independent assurance, penetration testing and its sign-off are carried out by accredited CREST partners.

Build · Run · 24/7

01What we build

What the Security Lab builds.

Archetypes, named by what they do. Every engagement also carries the standards we apply in every lab.

  1. 01

    Secure development lifecycles

    Threat modelling, review and scanning built into the way your teams already ship.

  2. 02

    Threat models

    Structured models of what could go wrong in a system, kept current as the architecture changes.

  3. 03

    Secure code review

    Automated and human review on every pull request, with findings tracked to closure.

  4. 04

    DORA and FCA resilience evidence

    Mapping, scenario testing and documentation that demonstrate operational resilience, produced as part of delivery.

  5. 05

    Certification readiness

    Gap analysis and remediation so you arrive at Cyber Essentials Plus or ISO 27001 assessment prepared.

  6. 06

    Hardening live systems

    Headers, TLS, identity, secrets and dependencies brought up to standard on platforms already in production.

02Services

Services and deliverables.

Concrete scopes with named outputs, so you know what you will hold at the end of each stage.

  • Security review

    Architecture and code review of an existing system, with prioritised findings and the fixes to close them.

    • Threat model
    • Findings report
    • Remediation pull requests
  • Secure delivery

    Security review, dependency scanning and secrets detection added as gates in your pipeline.

    • Pipeline security gates
    • Dependency and secrets scanning
    • Secure coding guide
  • Resilience and compliance evidence

    DORA, FCA SYSC 15A, Cyber Essentials Plus and ISO 27001 readiness work.

    • Gap analysis
    • Evidence pack
    • Remediation plan
  • Partner-attested penetration testing

    Scoping, coordination and remediation around tests performed by accredited CREST partners.

    • Test scope
    • Partner report
    • Retest of fixes

03Live tool: Security headers check

Check your headers.

Review the HTTP security headers a site sends and generate a hardened policy to copy. A useful first look, not a penetration test.

04Lab standard

The A* standard for this lab.

On top of fixed-price discovery, a named lead, code you own, test gates, observability, written decisions and an SLA-backed run retainer, this lab adds:

  1. 01

    A threat model for every significant system

    Written before the build starts and updated whenever the architecture changes.

  2. 02

    Secure code review on every pull request

    Automated security review runs on each pull request through the Claude Code GitHub Action, and an engineer reviews anything it flags.

  3. 03

    Dependency and secrets scanning

    Vulnerable packages and leaked credentials are caught in the pipeline, before they ship.

  4. 04

    Evidence as a by-product

    Reviews, scans and decisions are logged and retained, so audit evidence exists before anyone asks for it.

05Human sign-off

Where people sign off.

Independent assurance has to be independent. We prepare, coordinate and fix; accredited specialists test and attest.

  • Penetration test sign-offPenetration tests and their sign-off are performed by accredited CREST partners, independent of the team that built the system.
  • CertificationCyber Essentials Plus and ISO 27001 certificates are issued by accredited certification bodies. We prepare you; they assess.
  • Risk acceptanceAccepting a residual risk is a decision for your accountable executive, recorded in writing.
Assurance note

Penetration test sign-off is provided through accredited CREST partners. Aurion Labs does not issue security certifications and does not claim any on your behalf.

06FAQ

Questions, answered.

Do you carry out penetration tests yourselves?

No. We scope, coordinate and fix; the testing and sign-off are carried out by accredited CREST partners so the assurance is independent.

Can you help us achieve Cyber Essentials Plus or ISO 27001?

We prepare you with gap analysis, remediation and evidence. The certificate itself is awarded by an accredited body.

How does AI-assisted code stay secure?

Every change passes the same gates as hand-written code: automated security review, dependency and secrets scanning, tests and review by an engineer before it merges.

What does DORA evidence involve?

Mapping critical services and the systems and third parties they depend on, testing failure scenarios and recording the results in a form that supports DORA and FCA operational resilience obligations. Your firm owns the conclusions.

08Contact

Show us what needs protecting.

Your first call is with an engineer from the Security Lab, not a sales script. Bring the system, the deadline and the constraints.

hello@aurionlabs.io
+44 7832 617626 Milton Keynes, United Kingdom